Abstract
Middleboxes are intermediary network devices that facilitate traffic monitoring, filtering, and modification. They serve a broad spectrum of functions, ranging from benign tasks to highly controversial ones such as censorship. A solid body of work exists that describes methods to probe or identify middleboxes from remote including censorship middleboxes; similarly, much research has gone into fingerprinting network devices. However, there is comparatively little work that aims to understand which type of devices occurs in which networks. In this study, we choose to investigate middleboxes that reside in networks reported for network interference. We use yarrpbox, a scanning tool, to detect middleboxes and map them to vendors utilizing third-party datasets. Covering more than 500 Autonomous Systems reported for interference, we identify about 250 middleboxes, which we study in detail. We find that the location of middleboxes across countries does not correlate to the Internet Freedom Index, and we identify a distribution of vendors as well as a distribution across countries that differs markedly from previous reports. Most middleboxes in the reported networks are actually likely to serve multiple purposes, and this complexity calls for new measurement methodologies to determine whether the reported interference is a byproduct of some configuration or the primary purpose of a middlebox. We also identify a number of security issues in a number of devices, lending further support for the hypothesis that middleboxes can increase the attack surface of a network. We conclude with a discussion of directions to understand middlebox deployment with further measurements.
| Original language | English |
|---|---|
| Title of host publication | 2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) |
| Place of Publication | Piscataway, NJ |
| Publisher | IEEE |
| Pages | 176-186 |
| Number of pages | 11 |
| ISBN (Electronic) | 979-8-3315-9546-3 |
| ISBN (Print) | 979-8-3315-9547-0 |
| DOIs | |
| Publication status | Published - 2025 |
| Event | 10th IEEE European Symposium on Security and Privacy Workshops, EuroS&PW 2025 - Venice, Italy Duration: 30 Jun 2025 → 4 Jul 2025 Conference number: 10 |
Publication series
| Name | Proceedings - 10th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2025 |
|---|---|
| Publisher | IEEE |
| Volume | 2025 |
| ISSN (Print) | 2768-0649 |
| ISSN (Electronic) | 2768-0657 |
Conference
| Conference | 10th IEEE European Symposium on Security and Privacy Workshops, EuroS&PW 2025 |
|---|---|
| Abbreviated title | EuroS&PW 2025 |
| Country/Territory | Italy |
| City | Venice |
| Period | 30/06/25 → 4/07/25 |
Keywords
- 2025 OA procedure
- Network Analysis
- Network Interference
- Vendor Mapping
- Middleboxes